Skip to comments.New Mac OS X Trojan unearthed. Call it SabPub
Posted on 04/16/2012 9:00:32 PM PDT by iowamark
Here we go again.
Kaspersky Lab security researcher Costin Raiu has discovered another Mac OS X Trojan. Dubbed Backdoor.OSX.SabPub.a (or just SabPub, for short), the malware uses Java exploits to infect a Mac, connect to a remote Web site, and wait for instructions that include taking screenshots of the user's Mac and executing commands.
"The Java exploits appear to be pretty standard, however, (and) they have been obfuscated using ZelixKlassMaster, a flexible and quite powerful Java obfuscator," Raiu wrote on the Securelist blog. "This was obviously done in order to avoid detection from anti-malware products." Related stories
Raiu's discovery comes as Mac users are on high alert over the Flashback Trojan, which reportedly infected over 600,000 Macs worldwide. That exploit, which also uses Java, is capable of nabbing user passwords and other information from their Web browser or some applications. Apple on Friday released a tool designed to remove Flashback from infected machines. Prior to that launch, it was believed that 270,000 Macs were infected with the Trojan, down significantly from its height.
In a follow-up post on Securelist yesterday, Raiu provided a bit more information on SabPub to help differentiate it from Flashback. He reported that there are at least two SabPub variants in the wild today, including one that dates back to February. The malware appears to be delivered through targeted attacks, which should limit its ability to make widespread incursions a la Flashback.
Raiu also reported that the malware appears to be spreading through Word documents that exploit the CVE-2009-0563 vulnerability related to a stack-based buffer overflow in Office on the Mac.
"The most interesting thing here is the history of the second SabPub variant. In our virus collection, it is named '8958.doc.'" Raiu wrote on the blog. "This suggests it was extracted from a Word document or was distributed as a Doc-file."
Apple did not immediately respond to CNET's request for comment.
And so it begins...if you own a mac please by a 3rd party AV solution to protect your machine.
Just had an Apple software update for Java that said it removed malware.
Was that bogus?
swordmaker may be able to help.
My bet is that it was legit. OSX is being torn up by java malware right now.
So far everything is working, except the ice maker went out on the Sub Zero...
The problem is not exploit of the Apple's OS X but the Java that also runs on OS X that is being over hyped. Leo Laporte said you can actually disable Java!
Run the software update. Apple has addressed this problem in software updates.
If you disable Java system-wide, your safe. Ways to disable Java: http://osxdaily.com/2012/04/07/tips-secure-mac-from-virus-trojan/
Note, also that, contrary to the article, the Flashback NEVER, EVER infected 600,000 Macs, and the number was reduced to 227K, ADMITTED BY KASPERSKY, if even that! The number was ESTIMATED, and we are STILL not finding ANYONE in the real world who claims to have been infected! Where are the infected Macs????
This version requires an even OLDER unpatched version of JAVA... SHEESH!
Can you say "Proof of Concept?"
If you want on or off the Mac Ping List, Freepmail me.
Thanks, if that is so, good enough.... I wonder if Facebook video calling will still work though because looks like Skype plugin running on Java...?
That is a BS statement... re-analyzing the data provided by Doctor Web, it was found that they had exaggerated the threat by quite a bit... and that the number was 227,313 IF THAT... since no one is finding any infected machines in the WILD!
Doctor Web was claiming that you could submit your Mac's UUID to them and have them check with the CONTROL SERVER for the MacBOT to find out if you were infected, but KNOWN clean machines so submitted to their automatic checking site, some without JAVA being installed at all, were being reported as being members of the botnet!, including brand new Macs, right out of the box!
Thiscombined with the dearth of infected machines being reported on all the forumspretty much proves the botnet a hoax in my bookmade up of artificially generated UUIDs from the known range assigned to Apple Macs!
Thanks for Ping!! Keep me posted.
Even if that’s true that doesn’t change the fact that OSX now has confirmed malware in the wild.
“Just had an Apple software update for Java that said it removed malware.
Was that bogus?”
Nope, it was aimed at the Flashback malware. The Java update also removed the vulnerability, so attacks like Flashback won’t work.
This Cnet article was fairly worthless, as they didn’t make it clear that the latest Java patches remove the vulnerability.
There is apparently another variant that targets Microsoft Word for Mac, but you’re fine if you either don’t run Office, or simply don’t open documents from unknown sources. I didn’t see anything about a patch for this yet, it might be worth check Microsoft’s site for one.
I’ll also link a decent article on maximizing Mac security. It’s a bit overly paranoid in my view (I have Java and Flash installed, though I may get rid of standalone Flash). I guess at this point I’d recommend installing an anti-malware solution. I’m using Sophos, which is free and seems pretty lightweight.
“Even if thats true that doesnt change the fact that OSX now has confirmed malware in the wild.”
Not for a fully patched machine. There has been “theoretical” malware targeting Macs for years.
It is still a minuscule problem compared to the Windows free-for-all.